The mechanism
How a leveraged buyout transforms a data company
A private equity firm acquires a company, typically financing 60–80% of the purchase price with debt loaded onto the acquired company itself. It then extracts cash flow to service that debt and exits within 3–7 years. Applied to companies whose core asset is personal data, each feature of that structure maps to a specific privacy risk.
Debt loads create pressure to monetize data aggressively
When a PE firm buys a company using borrowed money, the debt doesn’t stay on the PE firm’s books — it gets loaded onto the acquired company. The company must generate enough cash to service those payments. For a company whose primary asset is personal data, the most liquid way to generate cash is to sell that data harder: to more customers, in more data categories, with fewer restrictions on use.
Private ownership removes public scrutiny
Public companies file 10-Ks with the SEC, disclose material cybersecurity incidents, and face pressure from shareholders and activist investors. Private, PE-owned companies do not. When a data broker is taken off a public exchange, the public loses its main window into how much data the company holds, how it’s secured, and who buys it. Several of the companies on this page were delisted specifically as part of their PE acquisition.
Roll-ups concentrate data under one owner
PE’s “buy-and-build” playbook acquires multiple companies in the same sector and merges them. This is efficient for investors and catastrophic for privacy: each consolidation combines previously separate datasets, increasing both the breach surface (one incident exposes everything) and correlation power (the ability to link records from formerly separate sources into a single profile on a person).
Short hold periods mean your data is always for sale
Because PE exits, data is permanently a saleable asset — not just during normal operations, but especially in bankruptcy, where a failed company’s dataset becomes an auctionable lot. The Near Intelligence bankruptcy (2023–24) is the modern example: 1.6 billion people’s location records were at risk of being sold to any bidder before a federal intervention blocked it.
The stack
Five layers of the same economy
The buyout model shows up at five layers of the surveillance economy — from the bulk file sold about you to software that can sit inside your phone. Each one is owned by private equity or a financial sponsor. The pattern is identical; only the layer changes.
Layer 1 · Consumer data
Who owns the brokers that hold your data
The largest US consumer and property data companies passed to financial sponsors and ad-holding conglomerates — most in the last five years. The acquisition typically coincides with, or is followed by, delisting from public exchanges.
The largest US property-data company was taken private in a $6 billion deal, financed largely with JPMorgan debt.
CoreLogic (NYSE: CLGX) — which holds property records, mortgage history, insurance data, and consumer profiles on nearly every US household — was acquired by Stone Point Capital and Insight Partners. The deal was announced February 4, 2021 and closed June 4, 2021. CoreLogic’s board approved the merger at $80 per share, representing an equity value of approximately $6.0 billion and a 51% premium to its prior unaffected share price. The transaction was financed with equity from both sponsors and committed debt financing from JPMorgan, reported as up to $5.5 billion. CoreLogic’s common stock was delisted from the NYSE on closing. In March 2025, the company rebranded as Cotality.
CoreLogic Ex-99.1 (SEC, Feb. 4, 2021) →One of the world’s largest marketing-data companies admitted to selling consumer data to fraud schemes for nearly a decade, then paid $150 million to resolve criminal liability.
Publicis Groupe acquired Epsilon from Alliance Data Systems (ADS) in 2019 for $4.4 billion. Before the sale closed, Epsilon’s direct-to-consumer unit had been knowingly selling consumer lists to mass-mailing fraud schemes targeting elderly people. On January 19, 2021, Epsilon entered a deferred prosecution agreement (DPA) with the DOJ, admitting to the conduct and agreeing to pay $150 million total — $127.5 million of which was designated to compensate victims. The conduct ran from July 2008 through July 2017. ADS indemnified Publicis for all costs under the original sale agreement. Two former Epsilon executives were later convicted at trial.
DOJ press release, Jan. 27, 2021 →Layer 2 · Location data
The most financially fragile sector — and the government’s preferred workaround
Location data companies aggregate smartphone movement records from app advertising networks and sell them without individual users’ knowledge. Federal and local agencies buy this data to track people’s movements without a warrant — because commercial purchase falls outside the warrant requirement that applies to compelled disclosure from carriers. When these companies fail financially, their datasets become auction lots available to any bidder.
The FTC has brought enforcement actions against the four largest players in this sector in 2024–2026. All four cases rest on the same structural violation: collecting location data from smartphone apps without informed user consent and then selling it, including to government buyers.
Case study: the bankruptcy risk
Near Intelligence: 1.6 billion people’s data nearly sold at auction
Near Intelligence — which claimed a dataset representing 1.6 billion people across 44 countries — went public via SPAC merger in early 2023. Seven months later, it filed for Chapter 11 bankruptcy in December 2023.
As Near entered bankruptcy, its location data became an asset available for sale to any bidder. On February 13, 2024, Senator Ron Wyden wrote to the FTC and SEC urging them to ensure the data was destroyed rather than sold. The FTC intervened: a subsequent bankruptcy court filing blocked the sale or transfer of Near’s consumer data. Near’s former executives were also disclosed to be under criminal investigation, according to a statement made by the company’s lawyer at the December 2023 bankruptcy hearing.
FTC enforcement actions
Three location-data brokers sanctioned in 14 months
Between December 2024 and May 2026, the FTC brought final orders against the three largest government-facing location-data brokers in the country.
Barred from selling sensitive location data; must delete historical data.
Gravy Analytics and its subsidiary Venntel collected precise geolocation data from over a billion mobile devices daily by purchasing it from advertising networks and data resellers — not by asking users. Venntel sold this data exclusively to public-sector clients: ICE, CBP, the FBI, and other DHS components used it to track individuals, including in the US–Mexico border region. The FTC charged both companies with violating the FTC Act by selling sensitive location data without verifiable user consent and inferring sensitive characteristics — health conditions, political activities, religious affiliation — from location patterns. The final order prohibits the companies from selling, disclosing, or using sensitive location data going forward and requires deletion of three years of historical data.
FTC press release, Jan. 14, 2025 →Nearly four years of litigation ended with a ban on selling sensitive location data without affirmative consent.
The FTC sued Kochava in August 2022 alleging it collected precise location data from hundreds of millions of mobile devices and sold it in ways that revealed visits to health facilities, places of worship, reproductive health clinics, homeless shelters, and addiction recovery centers. Kochava contested the case for nearly four years before settling. The Commission approved the stipulated final order 2–0 on May 4, 2026. Under the order, Kochava and its subsidiary Collective Data Solutions are prohibited from selling, licensing, or disclosing sensitive location data unless they obtain a consumer’s affirmative express consent and the data is used only to provide a service the consumer directly requested.
FTC press release, May 4, 2026 →State and local police access to location histories — without a warrant — for under $10,000 a year.
Fog Data Science is not a federal contractor — it targeted local police, sheriffs, and state highway patrols. A 2022 Electronic Frontier Foundation investigation based on over 100 public-records requests found that Fog sold access to its location database to at least 18 state, local, and federal law enforcement agencies. Fog claimed 15 billion data points daily from 250 million US devices, sourced from thousands of smartphone apps via advertising identifiers. One county paid $9,000 for a one-year license. EFF found no evidence that agencies obtained warrants before querying the system.
EFF investigation, Aug. 2022 →Layer 3 · Contractor tools
PE-backed tools agencies buy instead of warrants
Several of the key tools federal and local agencies use to access location data and build profiles on individuals are owned by private equity firms. The mechanism is the same as the location-broker sector: commercially available advertising data, bought without a warrant.
Locate X uses the advertising ID to query a device’s full location history — no warrant required.
Babel Street is backed by Veritas Capital, a PE firm with approximately $45 billion in assets under management that specializes in technology and national-security companies. Babel Street’s Locate X product aggregates mobile-device location data from advertising bid streams and SDK-based feeds and presents it as a queryable database. An operator can draw a geofence around any location and retrieve a list of every device that passed through — along with where those devices had been before and after. FOIA records obtained by journalists document Locate X contracts with the US Secret Service, the IRS’s Office of Foreign Assets Control (OFAC), US Customs and Border Protection, and ICE. CBP and ICE use it to track movement in the US–Mexico border region. Babel Street acquired OSINT firm Vertical Knowledge in January 2024.
EFF: How the Federal Government Buys Cell Phone Location Data →A Nebraska surveillance firm was combined with an Israeli intelligence-technology company in a PE-driven roll-up. ICE has spent over $5 million on their tools since 2021.
New York-based Spire Capital acquired a controlling interest in PenLink, a Lincoln, Nebraska communications-surveillance company, in April 2022. In July 2023, Spire used the same investment vehicle to acquire Cobwebs Technologies — an Israeli OSINT firm founded by former Israeli intelligence officers — for approximately $200 million and merged it into PenLink. The merger added Cobwebs’ two flagship products to PenLink’s suite: Tangles (an AI-powered open-source intelligence tool that scrapes the open, deep, and dark web and builds facial-recognition-enabled dossiers) and Webloc (which queries databases of mobile phone advertising-ID location data to track devices in a given area and time window). ICE has spent over $5 million on these tools since 2021, including a $2.3 million contract signed in fall 2025 for Tangles and Webloc.
PenLink press release, Jul. 11, 2023 →Layer 4 · Identity infrastructure
Thoma Bravo spent $12 billion building an identity platform in one year
This layer isn’t about tracking you — it’s the clearest example of the roll-up mechanism above, run at industrial scale. In 2022, Thoma Bravo, the dominant software-focused private equity firm, assembled a market-dominant identity-and-access-management (IAM) stack by acquiring three direct competitors in rapid succession, consolidating what had been an independent, fragmented market under a single private owner.
Identity software governs authentication: it determines who can log in to enterprise systems, how users are verified, and what access they have. It is defensive security software, not surveillance — but concentrating this stack into one PE-owned company puts the authentication infrastructure for hundreds of enterprises and government agencies under a single private owner with no public reporting obligations. The risk here is concentration and opacity, not tracking.
$6.9 billion. Identity governance and administration — managing who has access to what, across an enterprise.
SailPoint was taken private from the NYSE. At the time of acquisition, it was the leading independent provider of identity governance software for large enterprises.
IT Pro coverage of Thoma Bravo’s 2022 identity acquisitions →$2.8 billion. Customer and workforce identity — access management for large enterprises and their customers.
Ping Identity was also taken private from the NYSE. Its customer base included more than half of the Fortune 100.
$2.3 billion. Customer identity and access management — then merged into Ping Identity after US DOJ cleared the deal.
The ForgeRock acquisition triggered a US Department of Justice antitrust review because Ping Identity and ForgeRock were direct competitors. The DOJ cleared the transaction in August 2023. Thoma Bravo immediately announced it would merge the two companies. ForgeRock CEO Fran Rosch departed; Ping Identity founder Andre Durand led the combined entity. The three acquisitions totaled approximately $12 billion and brought SailPoint, Ping, and ForgeRock — formerly independent public companies — under a single private owner.
SecurityWeek: Thoma Bravo merges ForgeRock and Ping Identity, Aug. 2023 →Layer 5 · Spyware
Military-grade intrusion tools, PE-financed
At the far end of the surveillance spectrum are tools that don’t just track location — they silently extract encrypted messages, call logs, photos, and real-time microphone and camera access from a target’s phone. Two of the most prominent commercial spyware products are or have been owned by private equity firms.
Paragon / Graphite
$500 million acquisition moved Israeli spyware into a US PE portfolio in December 2024
Paragon Solutions is an Israeli company that makes Graphite — a zero-click spyware tool capable of extracting encrypted messages from Signal, WhatsApp, Telegram, and Facebook Messenger. It is a direct competitor to NSO Group’s Pegasus. Paragon was founded in 2019 by former members of Unit 8200, Israel’s signals intelligence unit.
In December 2024, US private equity firm AE Industrial Partners acquired Paragon. Per Citizen Lab’s review of corporate records, all shares in Paragon Israel were transferred on December 13, 2024 to a Delaware entity, Paragon Parent Inc. Reports from Israeli financial outlets Calcalist and Globes placed the upfront payment at $450–$500 million, with an additional earn-out potentially raising the total to $900 million. AE Industrial merged Paragon with its existing portfolio company REDLattice, a US cybersecurity firm.
ICE signed a $2 million contract with Paragon in September 2024. The Biden administration placed a stop-work order on that contract in October 2024; the Trump administration reactivated it on August 30, 2025.
NSO Group / Pegasus
A PE firm acquired and expanded the world’s most documented commercial spyware, then sold it to another PE firm
NSO Group is the Israeli company behind Pegasus, a spyware tool documented by Citizen Lab, Amnesty International, and others to have been used against journalists, human rights lawyers, and political figures in multiple countries. NSO’s ownership has changed at least three times since its founding, and a private equity firm was the catalyst for its expansion.
Francisco Partners acquired a majority stake in NSO Group for a reported ~$130 million and oversaw a period of rapid market expansion.
Francisco Partners is a San Francisco-based technology-focused PE firm. Under its ownership, NSO expanded sales of Pegasus to customers including governments in Mexico, Panama, and Saudi Arabia, per reporting by Reuters and the Financial Times. Francisco Partners also acquired Circles — a separate Israeli surveillance firm specializing in SS7 phone-network geolocation — for a reported ~$130 million in 2014, eventually merging it into the NSO corporate family.
Note: NSO Group is a private company. Acquisition prices for private transactions are reported by financial press (Reuters, FT, Bloomberg) rather than available in public filings.
NSO was sold to its founders, backed by UK PE firm Novalpina Capital, at a reported ~$1 billion valuation — then the Pegasus scandal unraveled Novalpina’s fund.
Novalpina Capital’s limited partner base included Oregon’s public pension fund, which had committed $233 million. As reporting on Pegasus’s use against civil-society targets accelerated in 2021 — culminating in the Forbidden Stories “Pegasus Project” — Novalpina’s limited partners voted to liquidate the fund. Control of NSO passed to consultancy Berkeley Research Group. NSO was added to the US Commerce Department’s Entity List in November 2021, restricting US companies from selling technology to it.
What you can do
The advertising identifier is the input that makes this pipeline run
Every company in the location and contractor sections of this page traces back to a single technical artifact: the mobile advertising identifier — the IDFA on iOS and the Google Advertising ID (GAID) on Android.
When you install an app that has location permission, that app can read your device’s advertising ID along with your coordinates. It can sell both to third-party brokers as part of its ad-monetization code. Brokers collect this stream from thousands of apps and link the different data streams to a single device using that persistent ID. That linked dataset is what Babel Street, Fog Data Science, PenLink’s Webloc, and the companies sanctioned by the FTC all sell.
Disabling the advertising identifier doesn’t make you invisible, but it severs the persistent link that makes location data commercially valuable. An app can still collect your location; it cannot tie that location to the same device’s data from other apps. That breaks the correlation the broker business model depends on.
Android: Settings → Privacy → Ads → “Delete advertising ID.” The exact path varies by manufacturer. On Pixel and stock Android, the option appears as “Delete advertising ID.”
For additional steps — tracker-blocking, limiting app location permissions to “while in use,” and choosing privacy-respecting apps — see our Tools and Guides pages.
Sources
Primary sources referenced on this page
Every factual claim on this page traces to one of the following. Links go to government filings, official press releases, court records, or original reporting. The label on each source indicates the document category.
-
CoreLogic Ex-99.1 — Definitive Merger Agreement with Stone Point Capital and Insight Partners https://www.sec.gov/Archives/edgar/data/36047/000119312521028672/d281311dex991.htm Press release filed as exhibit to Form 8-K. Confirms deal price ($80/share, ~$6.0B equity value, 51% premium), parties, and debt financing from JPMorgan.
-
Stone Point Capital and Insight Partners Complete Acquisition of CoreLogic https://www.stonepoint.com/news/stone-point-capital-and-insight-partners-complete-acquisition-of-corelogic/ Confirms close date (June 4, 2021) and NYSE delisting.
-
Who Owns CoreLogic: Current Ownership and Cotality Rebrand https://legalclarity.org/who-owns-corelogic-current-ownership-and-cotality-rebrand/ Documents the $5.5B JPMorgan debt tranche and the March 2025 Cotality rebrand. Cites the Stone Point press release as the primary source for debt figures.
-
Marketing Company Agrees to Pay $150 Million for Facilitating Elder Fraud Schemes (Epsilon DPA) https://www.justice.gov/usao-co/pr/marketing-company-agrees-pay-150-million-facilitating-elder-fraud-schemes Confirms DPA signed January 19, 2021; $150M total ($127.5M victims); conduct July 2008–July 2017; Epsilon acknowledged selling consumer lists to mass-mailing fraud schemes.
-
Alliance Data Systems Annual Report — Epsilon Indemnification Disclosure https://www.sec.gov/Archives/edgar/data/1101215/000110121522000038/ads-20211231x10k.htm Confirms ADS completed sale of Epsilon to Publicis on July 1, 2019 and agreed to indemnify Publicis for all DOJ investigation costs, paying $75M in January 2021 and $75M in January 2022.
-
Wyden urges FTC to safeguard abortion clinic visitors’ location data (Near Intelligence) https://thehill.com/policy/technology/4465856-wyden-ftc-abortion-clinic-visitor-location-data/ Reports Near Intelligence filed Chapter 11 in December 2023, and Wyden’s February 13, 2024 letter to FTC/SEC requesting data destruction rather than auction sale.
-
FTC Finalizes Order Prohibiting Gravy Analytics, Venntel from Selling Sensitive Location Data https://www.ftc.gov/news-events/news/press-releases/2025/01/ftc-finalizes-order-prohibiting-gravy-analytics-venntel-selling-sensitive-location-data Official finalization of consent order. Complaint originally December 3, 2024; final order January 14, 2025. Confirms prohibition on selling, disclosing, or using sensitive location data and requirement to delete historical data.
-
US FTC Cracks Down on Geolocation Data Brokers (Gravy / Venntel) https://www.govinfosecurity.com/us-ftc-cracks-down-geolocation-data-brokers-a-26971 Documents Venntel’s government clients (ICE, CBP, FBI) and how data was used to track individuals in the US–Mexico border region.
-
FTC to Ban Kochava and Subsidiary from Selling Sensitive Location Data https://www.ftc.gov/news-events/news/press-releases/2026/05/ftc-ban-kochava-subsidiary-selling-sensitive-location-data-settle-charges-they-sold-location-data Confirms 2–0 Commission vote; suit originally filed August 2022; settlement prohibits selling sensitive location data without affirmative express consent.
-
Inside Fog Data Science, the Secretive Company Selling Mass Surveillance to Local Police https://www.eff.org/deeplinks/2022/08/inside-fog-data-science-secretive-company-selling-mass-surveillance-local-police Based on 100+ FOIA requests. Documents Fog’s data sources (advertising IDs from 700+ apps), scale claims (250M US devices), pricing (starting under $10K/year, one county paid $9K), and law enforcement client list.
-
How the Federal Government Buys Our Cell Phone Location Data https://www.eff.org/deeplinks/2022/06/how-federal-government-buys-our-cell-phone-location-data Maps the government’s use of Venntel and Babel Street; documents known agency contracts with both.
-
The US Treasury Is Buying Private App Data to Target and Investigate People (Babel Street / Locate X) https://theintercept.com/2021/11/04/treasury-surveillance-location-data-babel-street/ Documents IRS/OFAC Babel Street contracts through FOIA. Confirms Locate X use and quotes internal contract description of how it functions.
-
EPIC FOIA: CBP Babel Street Location-Tracking Service https://epic.org/documents/epic-foia-cbp-babel-street-location-tracking-service/ Summarizes CBP and ICE Babel Street contracts confirmed through EPIC FOIA litigation; describes both Babel X and Locate X products.
-
Babel Street — Veritas Capital Investment https://www.cbinsights.com/company/babel-street/financials Documents Veritas Capital as investor in Babel Street’s acquisition financing round; confirms Vertical Knowledge acquisition (January 2024).
-
Cobwebs Technologies Joins PenLink to Expand Its Digital Investigative Platform https://www.penlink.com/press-release/cobwebs-technologies-joins-penlink-to-expand-its-digital-investigative-platform/ Official announcement of Cobwebs acquisition through Spire Capital, effective July 11, 2023. Confirms Spire Capital as the capital partner for both companies.
-
This Nebraska Company Is Supplying ICE with Surveillance Tech https://flatwaterfreepress.org/this-nebraska-company-is-supplying-ice-with-surveillance-tech/ Confirms Spire Capital took controlling stake in PenLink in 2022; Cobwebs acquisition in 2023; ICE $2.3M contract for Tangles and Webloc signed fall 2025.
-
Thoma Bravo Makes ‘Practical’ Decision to Merge ForgeRock Into Ping Identity https://www.darkreading.com/cybersecurity-operations/thoma-bravo-practical-decision-merge-forgerock-into-ping-identity Confirms all three deal prices (SailPoint $6.9B, Ping Identity $2.8B, ForgeRock $2.3B), the DOJ antitrust inquiry triggered by the ForgeRock deal, and the subsequent merger of ForgeRock into Ping.
-
ForgeRock Definitive Agreement to Be Acquired by Thoma Bravo for $2.3 Billion https://www.sec.gov/Archives/edgar/data/1543916/000119312522260580/d399542dex991.htm Press release as SEC exhibit. Confirms deal price ($23.25/share, $2.3B), Thoma Bravo’s AUM at time ($122B as of June 30, 2022), and transaction structure.
-
Virtue or Vice? A First Look at Paragon’s Proliferating Spyware Operations https://citizenlab.ca/research/a-first-look-at-paragons-proliferating-spyware-operations/ Reviews corporate records confirming all Paragon Israel shares transferred December 13, 2024 to Paragon Parent Inc. (Delaware). Notes AE Industrial Partners’ intent to merge Paragon with REDLattice.
-
Israeli spyware maker Paragon bought by US private equity giant AE Industrial Partners https://techcrunch.com/?p=2931960 Cites Calcalist ($500M upfront) and Globes ($450M upfront, potential $900M total) reporting on deal value; confirms AE Industrial Partners as acquirer.
-
ICE Reinstates Contract with Spyware Vendor Paragon https://www.infosecurity-magazine.com/news/ice-reinstated-spyware-paragon/ Documents the ICE–Paragon contract lifecycle: signed September 2024, Biden stop-work order October 2024, Trump administration reactivation August 30, 2025.
Get involved
It’s free, open to everyone at Pitt, and joining takes about a minute.
No dues, no experience needed. Come to a meeting, or leave your name and we’ll tell you when the next one is.